this post was submitted on 14 Feb 2024
264 points (89.3% liked)

Technology

59709 readers
2983 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Passkeys: how do they work? No, like, seriously. It’s clear that the industry is increasingly betting on passkeys as a replacement for passwords, a way to use the internet that is both more secure and more user-friendly. But for all that upside, it’s not always clear how we, the normal human users, are supposed to use passkeys. You’re telling me it’s just a thing... that lives on my phone? What if I lose my phone? What if you steal my phone?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 6 points 9 months ago (2 children)

We're supposed to take security advice from someone for freely gave their password out?

But in all seriousness yes phrases are better. You don't need the money symbol 1234t67890 especially if it makes it harder to remember.

You can even have each phrase be the website. TargetSucksMonkeyDick, BestBuySucksMonkeyDick are secure passwords.

[–] [email protected] 6 points 9 months ago

BestBuySucksMonkeyDick is the password I use on my luggage!

[–] [email protected] 6 points 9 months ago (1 children)

Which is KIND OF ok unless someone looks at a password breech list and figures out your super simple pattern. And I'm sure the rise of AI being used in password breech attacks will just make it more automated.

Real, true, random passwords/tokens is really the only way to actually be safe. Which means you have to use a password generator, AND something to save the password.

[–] [email protected] 1 points 9 months ago

unless someone looks at a password breech list and figures out your super simple pattern.

Don't simply put the site's name there. Put a similar sounding easy to remember word, a synonym, rhyming slang, the first and last letters of the site's name plus the number of letters in the domain name, whatever.